20.13 Ensure 'Audit records must be backed up to a different system or media than the system being audited'

Information

This policy setting ensures that audit records are backed up to a different system or media than the system being audited.

Rationale:

Protection of log data includes assuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Impact:

A secondary system that has enough resources to store large amounts of log data will be needed.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Establish and implement a process for backing up log data to another system or media other than the system being audited.

Default Value:

N/A




Additional Information:

Microsoft Windows Server 2019 Security Technical Implementation Guide:
Version 2, Release 1, Benchmark Date: November 13, 2020

Vul ID: V-205799
Rule ID: SV-205799r569188_rule
STIG ID: WN19-AU-000010
Severity: CAT II

See Also

https://workbench.cisecurity.org/files/3345

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-6(3), CSCv7|6.5

Plugin: Windows

Control ID: c81235c05f6a164dd453c5d1d37cf9e72883eb8c4dd2edd0482c4ccb9617c53e